Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes capabilities that include network access, local file writes, and shell execution via ffmpeg, but it does not declare permissions explicitly. This creates a transparency and governance gap: operators and users cannot accurately assess the trust boundary or execution risk before enabling the skill. In this context, the risk is increased because the skill fetches arbitrary remote URLs, invokes external tooling, and writes outputs locally.
